PRIVACY POLICY

Welcome to our website yoox.com (the Site). Your privacy and the security of your personal data are very important to YOOX NET-A-PORTER GROUP S.p.A. (“YOOX”), so we collect and manage your personal data with the utmost care and take specific measures to keep it safe. Below you will find the main information on the processing of your personal data by YOOX in relation to your browsing of yoox.com and the use of the services offered. For detailed information on how YOOX manages your personal data, please read our Privacy Notice. We also ask you to read the "Cookie Policy", the "General Conditions of Use" of the yoox.com website and "Myoox Terms and Conditions of Use", which contain detailed information regarding the conditions relating to our services. Some services may be subject to specific legal terms, in which case we will give you all the appropriate information from time to time.

Who is the Data Controller? Below is the main information on the processing of your personal data carried out by YOOX NET-A-PORTER GROUP S.p.A. with headquarters at via Morimondo n. 17 - 20143 Milano (Italia) C.F. e P.IVA n. 02050461207 (“YOOX”), as Data Controller. For any clarification, question or requirement related to your privacy and the processing of your personal data, you can contact us at any time by sending a request to our Customer Care by selecting "privacy", by calling 0800 046 3688 or by writing to the address of YOOX.

If you wish, you can also contact our Data Protection Officer (DPO) by writing to "Data Protection Officer" at the address above, or by e-mail to the DPO address.

What data do we process and why? The personal data that YOOX processes is that which you provide to us when you conclude an order and purchase goods, and that which we collect as you browse or use the services offered on yoox.com. YOOX can then collect data about you, for example, personal details such as name and surname, shipping address and billing address, browsing data and your purchase habits. Your personal data is processed for the following purposes: - conclude and execute the purchase contract for goods offered on yoox.com; - provide you with the services of yoox.com such as subscription to the newsletter; - allow registration to the site and use of services reserved for registered users; - manage your requests forwarded to our Customer Service. In the aforementioned cases, the processing of your personal data is legitimate as it is necessary to execute an agreement with you or to provide you with the service that you have specifically requested. We also conduct statistical surveys and analyses with data in aggregate form to understand how users interact and use the site, in order to improve our offer and our services. However, only with your express consent will we process your personal data to: - carry out commercial and promotional communication activities; - customise the site and the commercial offers based on your interests.

Who will process your data? Your personal data is processed by personnel duly authorised by YOOX as Data Controller. For organisational and functional needs related to the provision of services on yoox.com, your data could also be processed by our suppliers. The latter have been evaluated and chosen by YOOX for their proven reliability and competence. Some of these subjects may also be based in non-EU countries and, in these cases, the transfer of your personal data in these countries is carried out in compliance with the guarantees provided by law.

How long do we keep your data? We keep your personal data for a limited period of time depending on the purpose for which it was collected, at the end of which your personal data will be deleted or otherwise rendered anonymous in an irreversible way. The retention period is different depending on the processing purpose: for example, the data collected during the purchase of goods on yoox.com is processed until the conclusion of all administrative and accounting formalities are therefore stored in accordance with local tax legislation (ten years), that which is used to send you our newsletter until you ask us to stop sending it. See our Privacy Policy for more information.

What are your rights? At any time, depending on the specific processing, you may: revoke your consent to the processing, know which of your personal data we have in our possession, its origin and how it is used, request the update, correction or integration and in the cases provided for by the current provisions, the cancellation, the limitation of processing or oppose their processing. If you wish, you can request to receive your personal data in possession of YOOX in a format readable by electronic devices and, where technically possible, we can transfer your data directly to a third party indicated by you.

If you believe that the processing of your personal data has been carried out illegally, you can file a complaint with one of the supervisory authorities responsible for compliance with the rules on personal data protection. In Italy, the complaint can be presented to the Italian Data Protection Authority (http://www.garanteprivacy.it/).

This information may be subject to changes and additions over time, so we invite you to check the contents periodically. Where possible, we will try to immediately inform you of any changes made.

Privacy Notice

1. General informationWho is the Data Controller? YOOX NET-A-PORTER GROUP S.p.A. (“YOOX”) with headquarters at via Morimondo n. 17 - 20143 Milano (Italia) C.F. e P.IVA n. 02050461207 (“YOOX”) is the Data Controller, that is, the subject which decides how and why to process your personal data. You can always contact YOOX by writing to the above address, calling 0800 046 3688 or writing to our Customer Care and selecting “privacy”. Who is the Data Protection Officer? YOOX has appointed a Data Protection Officer. If you wish, you can contact the Data Protection Officer (“DPO”) of YOOX for any request regarding the protection of your personal data and the exercise of your rights, by writing to "Data Protection Officer" at the address above, or by e-mail to the DPO address.2. What personal data do we collect?The categories of personal data that YOOX collects and processes when you browse or purchase on yoox.com are as follows: a) we collect the personal data necessary to conclude and execute your purchase on yoox.com such as name and surname, e-mail address, shipping address, billing address, telephone and payment details; b) we collect your e-mail address when you sign up for our newsletter service; c) we process the personal data you provide us when you contact our Customer Service to provide the assistance requested; d) upon your consent, we collect and use your personal data for marketing purposes; e) for the registration of your Myoox account, we collect your name and surname, your e-mail address, password and your date of birth. If you are a registered user, we collect information about your access to the reserved part of ​​the site. With your express consent, by analysing your personal data we can process information regarding your interests and preferences with respect to our products and services in order to present proposals and offers in line with your tastes. In case of authentication to the Myoox account through external social networks, we collect the data necessary for registration/authentication through Facebook and Google. We also collect information about you from third parties and, in particular, from Facebook and Google. This information includes the following data categories: e-mail address. f) we collect information about your browsing on yoox.com, such as the pages you visit and how you interact with the single page and we save this information on our servers. g) in the event that you provide personal data of third parties to YOOX___, for example in cases where you decide to purchase a product to be delivered to a friend, or to give a gift, YOOX will arrange for the third party to deliver the Privacy Notice at the time of the first communication. We remind you that the use of personal data of third parties is subject to the discipline regarding the protection of personal data. We inform you that YOOX does not process personal data relating to minors. If you access yoox.com and use the services offered by YOOX, you declare that you are of legal age.3. How do we use the personal data collected?YOOX collects and processes your personal data for the following purposes: a) complete and execute contracts for the purchase of products offered on yoox.com. When you make a purchase, we ask you for the personal data needed in order to execute the contract. Our activities include payment processing, anti-fraud checks if you choose to pay by credit or debit card, invoicing, product shipments and the management of returns, if applicable. b) register with the Website and access the services offered to registered users. You can register with the Website by inputting certain personal information needed to guarantee your identity and use the services offered to registered users. c) supply the services offered on yoox.com and on the App. Depending on the specific service requested by you and its characteristics, YOOX needs to collect certain personal data in order to provide that service. d) manage requests made to our Customer Service centre, which uses the personal data provided by you to satisfy your requests for information and support. e) submit CVs. If you send us your CV for consideration when applying for a vacancy, we will use the information contained in your CV solely for that purpose. Your CV will be retained for a maximum of six months, after which it will be deleted: if you wish, you can of course send us a new, updated version. f) statistical analyses and investigations. We will use certain information about your use of the Website to carry out statistical analyses and investigations, with a view to improving our offers and services; g) send commercial and promotional communications (so-called soft spam) following the purchase of our products. Following the purchase of a product from our Website, we will send messages to the e-mail address provided by you, containing our commercial proposals regarding related products and services. h) with your express consent, we may use the addresses provided by you to send commercial communications about our products and services, in order to update you about news, latest arrivals, exclusive products, offers and promotions. In addition, again with your consent, we may use your contact details when carrying out market research and satisfaction surveys, with a view to improving our services and our relations with users. These communications will only be made in the manner chosen by you (e-mail, text message, telephone, post, WhatsApp). i) solely with your consent, YOOX may customise your experience as a registered user of yoox.com, making early bird and other offers consistent with your tastes and sending you personalised commercial messages that address your interests. These communications will only be made in the manner chosen by you (e-mail, text message, telephone, post, WhatsApp). We will base this personalisation on an analysis of your previous purchases and the other information described in the previous section entitled “What personal data do we collect?”. See the section entitled “Your Myoox profile” for further information about this data and the way it is processed. Should you initially authorise the activities described in points h) and i) and subsequently no longer wish to receive messages from YOOX, or merely wish to restrict the manner in which you are contacted, you can block the above communications at any time by clicking on the “unsubscribe” link found at the foot of each message. You can also do this by accessing your Myoox account, calling YOOX on 800 780243, contacting our Customer Service centre and selecting “privacy”, or writing to the above address. Please note that you may receive further messages from us after submitting your unsubscribe request, as certain communications may have already been planned and our systems might take time to implement your request. With regard to all the above activities, we will mainly process your personal data using IT and electronic equipment; the tools used by us guarantee high levels of security, in full compliance with the relevant current regulations.4. Your Myoox profileWhen creating your Myoox, we offer you the possibility to use the following services: • My orders: follow the shipment of your orders, change or return items that are not for you and see your order history. • Dream Box: save the items you most want and keep an eye on their availability. • Secret Preview: get a preview of new arrivals each week. • Moneyoox: choose the fastest and easiest refund method for the items you want to return. Use the virtual credit obtained for your next orders. • Première: save your searches while shopping and stay updated on new arrivals of the items that interest you most. • My data: manage your registration data. • My addresses: save or modify your addresses to always have them available and complete your purchases faster. • My cards: save or modify the cards you use for your purchases and complete your orders quickly and always in a secure manner. • My Sizes: create your profiles and only find the items in your perfect size. With your express consent, YOOX will be able to customise your experience and the contents of commercial communications and offers that you will see when you browse on yoox.com as a registered user, based on your interests. This activity allows you to facilitate the search for products and services that are of more interest to you and at the same time allows us to improve our offer for you. Personalisation is made possible by the analysis of your personal data in our possession, described in the previous paragraph “What personal data do we collect?”. In particular, the information on purchases you have made in the past and those relating to the sections of the site you visit most often or the services you use most often help us to understand which products and services you are most interested in. To ensure that the information in our possession is correct and allow us to perform the activities described above, we invite you to access the “My profile” section of your Myoox and, if you deem it necessary, to update them.5. Lawfulness of processingWe will only process your personal data if one of the following conditions envisaged in the current regulations is satisfied: a) to complete and execute a contract with you. When we process your data in order to complete and execute a purchase contract with you, we take care to use solely the minimum information needed for that purpose. This approach renders lawful the processing of your personal data for the following activities: - complete and execute the contract for the purchase of products offered on yoox.com; - register with the Website and access the services offered to registered users; - supply the services offered on yoox.com and on the App; - manage requests made to our Customer Service centre. The provision of your personal data for the above activities is a contractual obligation. You are free to decide whether or not to give us your data but, in the absence of the requested data, we will be unable to complete or execute the contract or your requests. This means that you will be unable to purchase the products or benefit from the services provided by YOOX, and that YOOX will be unable to manage your requests; b) to satisfy a legal obligation. If you complete a contract for the purchase of goods from yoox.com, your data will be processed in order to satisfy the legal obligations imposed on YOOX, in compliance with the tax and other regulations applicable to YOOX. You are free to decide whether or not to enter into a contract with us and give us your data but, if you do, your data is necessary and will be processed in order to satisfy the legal obligations imposed on YOOX. CVs spontaneously sent to us will be processed in order to assess candidates for vacant job positions at YOOX. This activity is expressly authorised by a law that, in those circumstances, does not require consent to be obtained from the person to whom the personal data relates. You are free to decide whether or not to send us your CV but, in its absence, we will be unable to assess your candidacy for any job vacancies at YOOX; c) in our legitimate interests. If you purchase products from yoox.com using a debit or credit card, some of your personal data may be processed for anti-fraud purposes: we have a legitimate interest in doing that in order to prevent and tackle any fraudulent activity. For internal administrative purposes, your data may be processed by companies belonging to the YOOX NET-A-PORTER GROUP. d) based on your consent. We will carry out the processing described below solely if you have given us your express consent: • marketing activities, opinion surveys and market research; • analysis of your browsing and consumption habits when logged on under your Myoox profile, in order to personalise your experience on our Website. The provision of your personal data for the above activities is entirely optional. You are free to decide whether or not to give us you data for the above purposes but, in its absence, YOOX will be unable to carry out marketing activities, opinion surveys or market research, or analyse your habits.6. Who will process your data?Your personal data will be processed by YOOX internal staff who are specifically trained and authorised to process. Your personal data will also be transmitted to third parties that we use to provide our services; these subjects have been adequately selected and offer a guarantee of compliance with the rules on the processing of personal data. These persons have been appointed as data controllers and carry out their activities according to the instructions given by YOOX and under its control. The third parties in question belong to the following categories: banking operators, internet providers, companies specialised in IT and telematic services; couriers; companies that carry out marketing activities; companies specialised in market research and data processing. Your data may be transmitted to police and judicial and administrative authorities, in accordance with the law, for the detection and prosecution of crimes, the prevention and protection from threats to public security, to allow YOOX to ascertain, exercise or defend a right in court, as well as for other reasons related to the protection of the rights and freedoms of others.7. APP version of the WebsiteIn addition to the data mentioned in the section entitled “What personal data do we collect?”, when you use the App version of our Website YOOX may: a) with your express consent, collect your personal data for marketing purposes, in order to send push notifications to your device. You may deactivate push notifications at any time by changing the settings on your mobile device; b) with your express consent, collect information automatically, including your traffic data and the time spent browsing the App, or your IP address, in order to improve our offer of products and services; c) in order to use the service, collect the information you wish to give us, such as your photograph and the sizes of your clothing and accessories. We will retain that data until you specifically decide to delete your profiles or request the deletion of your Myoox account.8. Web push notificationDepending on which device you use, you may receive, upon giving your consent, push notifications regarding our offers, new items, your wish list and your cart. To deactivate notifications, depending on the platform and/or browser used, follow the steps listed below: - Desktop: Right-click on notification > disable notifications from www.yoox.com - Mobile: Access the notification center > Site parameters > Notifications > Block notifications from www.yoox.com - Common browsers: • Chrome: Settings > Show Advanced Settings > Privacy – Content Settings > Notifications - Manage exceptions > Enter www.yoox.com and select “Block” • Firefox: Options > Content > Notifications – Select > www.yoox.com – “Block” • Safari: Preferences > Notifications > From here select "Deny"9. Extra-EU data transferSome of the third parties listed in the previous paragraph “Who will process your data?” may be located in countries outside the European Union that nevertheless offer an adequate level of data protection, as established by specific decisions of the European Commission (http://www.garanteprivacy.it/home/provvedimenti-normativa/normativa/normativa -comunitaria-and-intenazionale / transfer-value-to-countries-third # 1). The transfer of your personal data to countries that do not belong to the European Union and that do not ensure adequate levels of protection will be performed only after conclusion between YOOX and said subjects of specific agreements, containing safeguard clauses and appropriate safeguards for the protection of your personal data which are so-called "standard model clauses", also approved by the European Commission, or if the transfer is necessary for the conclusion and execution of an agreement between you and YOOX (for the purchase of goods offered on our site, for registration on the website or the use of services on the website) or for the management of your requests.10. How long do we keep the data?We keep your personal data for a limited period of time, which is different depending on the type of activity that involves the processing of your personal data. After this period, your data will be permanently erased or otherwise rendered anonymous in an irreversible way. Your personal data is stored in compliance with the following terms and criteria: a) data collected to conclude and execute agreements for the purchase of goods on yoox.com: until the administrative and accounting formalities have been completed. The billing data will be kept for ten years from the billing date; b) data of the registered user: the data will be stored until you request cancellation of your Myoox profile; c) data relating to the payment: up to the certification of the payment and the conclusion of the related administrative and accounting formalities resulting from the expiration of the right of withdrawal and the terms applied for the contestation of the payment; d) data collected in the context of the use of services offered on yoox.com to the user: these data are retained until the termination of service or cancellation of the subscription to the service by the user; e) data related to user requests to our Customer Care: the data useful to assist you will be kept until your request is met; f) CV: for six months from receipt; g) data used for commercial communication activities towards users who purchase products on yoox.com (soft spam): this data is kept until the termination of service or the exercise of the opposition by unsubscription by the user; h) data provided for commercial communications activities, opinion polls and market research: up to the request by the user to interrupt the activity and in any case within 2 years from the last interaction of any kind of user with YOOX; i) data used to personalise the site and to show customised commercial offers: as long as the user does not request the termination of the activity and in any case within two years from the last interaction of any kind of user with YOOX; j) data used for carrying out market research and surveys for the detection of satisfaction: as long as the user does not request the termination of the activity. In any case, for technical reasons, the termination of the processing and the subsequent cancellation or irreversible anonymisation of the related personal data will be final within thirty days of the terms indicated above.11. Your rightsYou can exercise your rights at any time with reference to the specific processing of your personal data by YOOX. Below is their general description and how to practice them. a) Access your data and modify it: you have the right to access your personal data and to request that it be correct, modified or integrated with other information. If you wish, we will provide you with a copy of your data in our possession. b) Revoke your consent: you can revoke a consent you have given for the processing of your personal data in relation to any activity for marketing purposes at any time. In this regard, we remind you that marketing activities are considered the sending of commercial and promotional communications, the conduct of market research and surveys for the detection of satisfaction for the customisation of the website and commercial offers according to your interests. Once we receive your request, it will be our duty to promptly cease to process your personal data based on this consent, while different processing or that which is based on other assumptions will continue to be carried out in full compliance with the provisions in force. c) Opposition to the processing of your data: you have the right to object at any time to the processing of your personal data made on the basis of our legitimate interest, explaining the reasons that justify your request; before accepting it, YOOX will have to evaluate the reasons for your request. d) Delete your data: you may request the cancellation of your personal data in the cases provided for by current legislation. Once your request has been received and examined and if it is legitimate, it will be our duty to timely cease to process your personal data and to delete it. e) Request of restriction of the processing: in this case, YOOX will continue to keep your personal data but will not process it, unless it is subject to your different request and the exceptions established by law. Processing of your personal data can be limited when you dispute the accuracy of your personal data, when the processing is illegal but you oppose the cancellation of your data, when we no longer need your personal data but you need to exercise your right in court and when you oppose your processing, in the period in which we evaluate the reasons for your request. f) Request of data transfer to other party than YOOX ("right to data portability"). You can ask to receive your data that we process based on your consent or on the basis of an agreement with you in a standard format. If you wish, where technically possible and at your request, we may transfer your data directly to a third party that you indicate. In order to exercise some of your rights described above you can access your Myoox or alternatively you can contact us by calling 0800 046 3688 or writing to our Customer Care and selecting “privacy”, or by writing to the address of the Data Controller above. In order to ensure that our users' data is not infringed or illegitimate by third parties, we will ask you for some information to be sure of your identity before accepting your request to exercise one of the rights indicated.12. Security measuresWe protect your personal data with specific technical and organisational security measures, aimed at preventing your personal data from being used illegitimately or fraudulently. In particular, we use security measures that guarantee: the pseudonymisation or the encryption of your data; the confidentiality, integrity, availability of your data as well as the resilience of the systems and services that process them; the ability to restore data in the event of a data breach. Furthermore, YOOX agrees to test, verify and regularly evaluate the effectiveness of technical and organisational measures in order to guarantee continuous improvement in the security of processing.13. ComplaintsIf you believe that the processing of your personal data has been carried out illegally, you can file a complaint with one of the supervisory authorities responsible for compliance with the rules on personal data protection. In Italy, the complaint can be presented to the Italian Data Protection Authority. More information on the presentation methods are available on the website of the Italian Data Protection Authority, at http://www.garanteprivacy.it.14. Changes to this informationThe constant development of our services may lead to changes in the characteristics of the processing of your personal data described up to now. Consequently, this privacy policy may be subject to changes and additions over time, which may also be necessary with regard to new regulatory measures regarding the protection of personal data. Therefore, we invite you to periodically check the contents: where possible, we will try to inform you promptly on the changes made and their consequences in In any case, the updated version of the privacy statement will be published on this page, with indication of the date of its last update.15. Legislative references and useful linksThe processing of your personal data is carried out by YOOX in full compliance with the regulations on the matter pursuant to the General Data Protection Regulation (EU) 2016/679, the rules on the processing of Italian personal data and the provisions of the Italian Data Protection Authority (http://www.garanteprivacy.it).